Skip to content

[fga] check some admin functions #18562

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 21, 2023
Merged

[fga] check some admin functions #18562

merged 1 commit into from
Aug 21, 2023

Conversation

svenefftinge
Copy link
Contributor

@svenefftinge svenefftinge commented Aug 21, 2023

Description

adds permission checks for:

  • adminBlockUser(req: AdminBlockUserRequest)
  • adminVerifyUser(id: string)
  • adminModifyRoleOrPermission(req: AdminModifyRoleOrPermissionRequest)
  • adminModifyPermanentWorkspaceFeatureFlag(req: AdminModifyPermanentWorkspaceFeatureFlagRequest)
  • adminCreateBlockedRepository(urlRegexp: string, blockUser: boolean)
  • adminDeleteBlockedRepository(id: number)
  • adminGetBlockedRepositories(req: AdminGetListRequest<BlockedRepository>)
  • adminGetTeams(req: AdminGetListRequest<Team>)
  • adminGetBillingMode(attributionId: string)
  • adminGetBlockedEmailDomains()
  • adminSaveBlockedEmailDomain(entry: EmailDomainFilterEntry)
Summary generated by Copilot

🤖 Generated by Copilot at e8f8742

This pull request adds installation-level and user-level permission checks using Spicedb and the Authorizer service. It also refactors some methods in the GitpodServerImpl and the TeamDB classes, and adds new tests and schema definitions for the new permissions.

Related Issue(s)

Fixes #

How to test

Documentation

Preview status

Gitpod was successfully deployed to your preview environment.

Build Options

Build
  • /werft with-werft
    Run the build with werft instead of GHA
  • leeway-no-cache
  • /werft no-test
    Run Leeway with --dont-test
Publish
  • /werft publish-to-npm
  • /werft publish-to-jb-marketplace
Installer
  • analytics=segment
  • with-dedicated-emulation
  • workspace-feature-flags
    Add desired feature flags to the end of the line above, space separated
Preview Environment / Integration Tests
  • /werft with-local-preview
    If enabled this will build install/preview
  • /werft with-preview
  • /werft with-large-vm
  • /werft with-gce-vm
    If enabled this will create the environment on GCE infra
  • with-integration-tests=all
    Valid options are all, workspace, webapp, ide, jetbrains, vscode, ssh. If enabled, with-preview and with-large-vm will be enabled.
  • with-monitoring

/hold

.createQueryBuilder("team")
.where("LOWER(team.name) LIKE LOWER(:searchTerm)", { searchTerm: `%${searchTerm}%` })
let queryBuilder = teamRepo.createQueryBuilder("team");
if (searchTerm) {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@geropl
Copy link
Member

geropl commented Aug 21, 2023

Testing now...

Copy link
Member

@geropl geropl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM, tested and works ✔️

@svenefftinge
Copy link
Contributor Author

/unhold

@roboquat roboquat merged commit 246d8ed into main Aug 21, 2023
@roboquat roboquat deleted the se/more-fga branch August 21, 2023 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants